Windows Program Compatibility Assistant records are produced when
application execution is evaluated by the Program Compatibility
Assistant. Executable paths, execution times, compatibility outcomes,
and available program metadata may be retained, allowing application
activity to be reviewed after the original executable has been moved or
removed.
Program Compatibility Assistant records can support the reconstruction
of software activity on a Windows system. Recorded executable paths and
last execution times may indicate when an application, installer, or
utility was launched or evaluated, while file descriptions, vendors,
versions, run statuses, AmCache identifiers, and resolver or exit
details can provide additional context. These records can be correlated
with AmCache, Prefetch, UserAssist, event logs, and file-system
artifacts to strengthen an execution timeline, although a PCA entry
alone should not be treated as proof of user intent.
Program Compatibility Assistant records can be recovered from the
following Windows locations:
%SystemRoot%\appcompat\pca\PcaAppLaunchDic.txt
%SystemRoot%\appcompat\pca\PcaGeneralDb0.txt
The files and the fields populated within their records may vary
according to the Windows version and the type of compatibility event
that was recorded.
This section will discuss how to use ArtiFast to extract Windows Program
Compatibility Assistant Records artifacts from Windows device files and
what kind of digital forensics insights can be gained from the
artifacts.
After a case has been created and evidence has been added for the
investigation, at the Artifact Selection phase, the Windows Program
Compatibility Assistant Records artifact parser can be selected:
Once the ArtiFast parser plugins complete processing the artifact for analysis, it can be reviewed via Artifact View or Timeline View, with indexing, filtering, and searching capabilities. Below is a detailed description of Windows Program Compatibility Assistant Records artifact in ArtiFast.
Program Compatibility Assistant Records
For more information or suggestions please contact: enes.turan@forensafe.com